@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

Autopsy and Realloc

Note:I translated Japanese into English using Google Translate.
Thank you, Google. 

Let's create a record labeled (realloc).

f:id:hideakii:20180924082623j:plain

Create Example folder and create several files in the folder. In the following, a long file name is set to create Index Allocation of $i30.

f:id:hideakii:20180924074405j:plain

f:id:hideakii:20180924074757j:plain

Copy frog.jpg to be used for testing to the F:\Example folder.

f:id:hideakii:20180924075141j:plain

Create a hard link to the frog.jpg file. Frog.jpg and sample.jpg are FILE record number 51.

f:id:hideakii:20180924075413j:plain

Delete the folder F:\Example. 

f:id:hideakii:20180924080117j:plain

If you check $i30, you can find Frog.jpg's $FN. Interesting, FTK Imager 4.1.1.1 does not display Frog.jpg.

f:id:hideakii:20180924080543j:plain

Check the display on Autopsy. Flags (Dir) is Unallocated, but Flags (Meta) is Allocated.

f:id:hideakii:20180924083452j:plain

 In addition, Frog.jpg is not displayed on the timeline of plaso-20180818-amd64.

 

Reference URL:

 

github.com

f:id:hideakii:20180924074042j:plain